CVE-2021-47274
published 2024-05-21CVE-2021-47274: In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered from severe…
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.26%
66.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
tracing: Correct the length check which causes memory corruption
We've suffered from severe kernel crashes due to memory corruption on
our production environment, like,
Call Trace:
[1640542.554277] general protection fault: 0000 [#1] SMP PTI
[1640542.554856] CPU: 17 PID: 26996 Comm: python Kdump: loaded Tainted:G
[1640542.556629] RIP: 0010:kmem_cache_alloc+0x90/0x190
[1640542.559074] RSP: 0018:ffffb16faa597df8 EFLAGS: 00010286
[1640542.559587] RAX: 0000000000000000 RBX: 0000000000400200 RCX:
0000000006e931bf
[1640542.560323] RDX: 0000000006e931be RSI: 0000000000400200 RDI:
ffff9a45ff004300
[1640542.560996] RBP: 0000000000400200 R08: 0000000000023420 R09:
0000000000000000
[1640542.561670] R10: 0000000000000000 R11: 0000000000000000 R12:
ffffffff9a20608d
[1640542.562366] R13: ffff9a45ff004300 R14: ffff9a45ff004300 R15:
696c662f65636976
[1640542.563128] FS: 00007f45d7c6f740(0000) GS:ffff9a45ff840000(0000)
knlGS:0000000000000000
[1640542.563937] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[1640542.564557] CR2: 00007f45d71311a0 CR3: 000000189d63e004 CR4:
00000000003606e0
[1640542.565279] DR0: 0000000000000000 DR1: 0000000000000000 DR2:
0000000000000000
[1640542.566069] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7:
0000000000000400
[1640542.566742] Call Trace:
[1640542.567009] anon_vma_clone+0x5d/0x170
[1640542.567417] __split_vma+0x91/0x1a0
[1640542.567777] do_munmap+0x2c6/0x320
[1640542.568128] vm_munmap+0x54/0x70
[1640542.569990] __x64_sys_munmap+0x22/0x30
[1640542.572005] do_syscall_64+0x5b/0x1b0
[1640542.573724] entry_SYSCALL_64_after_hwframe+0x44/0xa9
[1640542.575642] RIP: 0033:0x7f45d6e61e27
James Wang has reproduced it stably on the latest 4.19 LTS.
After some debugging, we finally proved that it's due to ftrace
buffer out-of-bound access using a debug tool as follows:
[ 86.775200] BUG: Out-of-bounds write at addr 0xffff88aefe8b7000
[ 86.780806] no_context+0xdf/0x3c0
[ 86.784327] __do_
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.46-1 (bookworm) | linux 5.10.46-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 0572fc6a510add9029b113239eaabf4b5bce8ec9 < 31ceae385556c37e4d286cb6378696448f566883 | 31ceae385556c37e4d286cb6378696448f566883 |
| linux | linux | >= 2e584b1a02eeb860e286d39bc408b25ebc5ec844 < edcce01e0e50840a9aa6a70baed21477bdd2c9f9 | edcce01e0e50840a9aa6a70baed21477bdd2c9f9 |
| linux | linux | >= 4.14.222 < 4.14.237 | 4.14.237 |
| linux | linux | >= 4.19.177 < 4.19.195 | 4.19.195 |
| linux | linux | >= 4.9.258 < 4.9.273 | 4.9.273 |
| linux | linux | >= 5.10.17 < 5.10.44 | 5.10.44 |
| linux | linux | >= 5.4.99 < 5.4.126 | 5.4.126 |
| linux | linux | >= 7c93d8cff582c459350d6f8906eea6e4cd60d959 < 43c32c22254b9328d7abb1c2b0f689dc67838e60 | 43c32c22254b9328d7abb1c2b0f689dc67838e60 |
| linux | linux | >= a0997a86f5c0085e183ddee5fb72091d584d3d16 < d63f00ec908b3be635ead5d6029cc94246e1f38d | d63f00ec908b3be635ead5d6029cc94246e1f38d |
| linux | linux | >= b220c049d5196dd94d992dd2dc8cba1a5e6123bf < b16a249eca2230c2cd66fa1d4b94743bd9b6ef92 | b16a249eca2230c2cd66fa1d4b94743bd9b6ef92 |
| linux | linux | >= b220c049d5196dd94d992dd2dc8cba1a5e6123bf < 3e08a9f9760f4a70d633c328a76408e62d6f80a3 | 3e08a9f9760f4a70d633c328a76408e62d6f80a3 |
| linux | linux | >= e46d433754420b4d6513ca389403de88a0910279 < 2d598902799886d67947406f26ee8e5fd2ca097f | 2d598902799886d67947406f26ee8e5fd2ca097f |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 4.14.222 < 4.14.237 | 4.14.237 |
| linux | linux_kernel | >= 4.19.177 < 4.19.195 | 4.19.195 |
| linux | linux_kernel | >= 4.9.258 < 4.9.273 | 4.9.273 |
| linux | linux_kernel | >= 5.10.17 < 5.10.44 | 5.10.44 |
| linux | linux_kernel | >= 5.11 < 5.12.11 | 5.12.11 |
| linux | linux_kernel | >= 5.4.99 < 5.4.126 | 5.4.126 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: tracing: Correct the length check which causes memory corruption
vendor_redhat·2024-05-21·CVSS 9.8
CVE-2021-47274 [CRITICAL] CWE-787 kernel: tracing: Correct the length check which causes memory corruption
kernel: tracing: Correct the length check which causes memory corruption
In the Linux kernel, the following vulnerability has been resolved:
tracing: Correct the length check which causes memory corruption
We've suffered from severe kernel crashes due to memory corruption on
our production environment, like,
Call Trace:
[1640542.554277] general protection fault: 0000 [#1] SMP PTI
[1640542.554856] CPU: 17 PID: 26996 Comm: python Kdump: loaded Tainted:G
[1640542.556629] RIP: 0010:kmem_cache_alloc+0x90/0x190
[1640542.559074] RSP: 0018:ffffb16faa597df8 EFLAGS: 00010286
[1640542.559587] RAX: 0000000000000000 RBX: 0000000000400200 RCX:
0000000006e931bf
[1640542.560323] RDX: 0000000006e931be RSI: 0000000000400200 RDI:
ffff9a45ff004300
[1640542.560996] RBP: 0000000000400200 R08: 0000000000023420
Debian
CVE-2021-47274: linux - In the Linux kernel, the following vulnerability has been resolved: tracing: Co...
vendor_debian·2021·CVSS 9.8
CVE-2021-47274 [CRITICAL] CVE-2021-47274: linux - In the Linux kernel, the following vulnerability has been resolved: tracing: Co...
In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered from severe kernel crashes due to memory corruption on our production environment, like, Call Trace: [1640542.554277] general protection fault: 0000 [#1] SMP PTI [1640542.554856] CPU: 17 PID: 26996 Comm: python Kdump: loaded Tainted:G [1640542.556629] RIP: 0010:kmem_cache_alloc+0x90/0x190 [1640542.559074] RSP: 0018:ffffb16faa597df8 EFLAGS: 00010286 [1640542.559587] RAX: 0000000000000000 RBX: 0000000000400200 RCX: 0000000006e931bf [1640542.560323] RDX: 0000000006e931be RSI: 0000000000400200 RDI: ffff9a45ff004300 [1640542.560996] RBP: 0000000000400200 R08: 0000000000023420 R09: 0000000000000000 [1640542.561670] R10: 0000000000000000 R11: 00000000
OSV
CVE-2021-47274: In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered fr
osv·2024-05-21·CVSS 9.8
CVE-2021-47274 [CRITICAL] CVE-2021-47274: In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered fr
In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered from severe kernel crashes due to memory corruption on our production environment, like, Call Trace: [1640542.554277] general protection fault: 0000 [#1] SMP PTI [1640542.554856] CPU: 17 PID: 26996 Comm: python Kdump: loaded Tainted:G [1640542.556629] RIP: 0010:kmem_cache_alloc+0x90/0x190 [1640542.559074] RSP: 0018:ffffb16faa597df8 EFLAGS: 00010286 [1640542.559587] RAX: 0000000000000000 RBX: 0000000000400200 RCX: 0000000006e931bf [1640542.560323] RDX: 0000000006e931be RSI: 0000000000400200 RDI: ffff9a45ff004300 [1640542.560996] RBP: 0000000000400200 R08: 0000000000023420 R09: 0000000000000000 [1640542.561670] R10: 0000000000000000 R11: 00000000
GHSA
GHSA-px85-vjfw-cm92: In the Linux kernel, the following vulnerability has been resolved:
tracing: Correct the length check which causes memory corruption
We've suffered
ghsa_unreviewed·2024-05-21
CVE-2021-47274 [CRITICAL] CWE-125 GHSA-px85-vjfw-cm92: In the Linux kernel, the following vulnerability has been resolved:
tracing: Correct the length check which causes memory corruption
We've suffered
In the Linux kernel, the following vulnerability has been resolved:
tracing: Correct the length check which causes memory corruption
We've suffered from severe kernel crashes due to memory corruption on
our production environment, like,
Call Trace:
[1640542.554277] general protection fault: 0000 [#1] SMP PTI
[1640542.554856] CPU: 17 PID: 26996 Comm: python Kdump: loaded Tainted:G
[1640542.556629] RIP: 0010:kmem_cache_alloc+0x90/0x190
[1640542.559074] RSP: 0018:ffffb16faa597df8 EFLAGS: 00010286
[1640542.559587] RAX: 0000000000000000 RBX: 0000000000400200 RCX:
0000000006e931bf
[1640542.560323] RDX: 0000000006e931be RSI: 0000000000400200 RDI:
ffff9a45ff004300
[1640542.560996] RBP: 0000000000400200 R08: 0000000000023420 R09:
0000000000000000
[1640542.561670] R10: 0000000000000000 R11: 00000
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/2d598902799886d67947406f26ee8e5fd2ca097fhttps://git.kernel.org/stable/c/31ceae385556c37e4d286cb6378696448f566883https://git.kernel.org/stable/c/3e08a9f9760f4a70d633c328a76408e62d6f80a3https://git.kernel.org/stable/c/43c32c22254b9328d7abb1c2b0f689dc67838e60https://git.kernel.org/stable/c/b16a249eca2230c2cd66fa1d4b94743bd9b6ef92https://git.kernel.org/stable/c/d63f00ec908b3be635ead5d6029cc94246e1f38dhttps://git.kernel.org/stable/c/edcce01e0e50840a9aa6a70baed21477bdd2c9f9https://git.kernel.org/stable/c/2d598902799886d67947406f26ee8e5fd2ca097fhttps://git.kernel.org/stable/c/31ceae385556c37e4d286cb6378696448f566883https://git.kernel.org/stable/c/3e08a9f9760f4a70d633c328a76408e62d6f80a3https://git.kernel.org/stable/c/43c32c22254b9328d7abb1c2b0f689dc67838e60https://git.kernel.org/stable/c/b16a249eca2230c2cd66fa1d4b94743bd9b6ef92https://git.kernel.org/stable/c/d63f00ec908b3be635ead5d6029cc94246e1f38dhttps://git.kernel.org/stable/c/edcce01e0e50840a9aa6a70baed21477bdd2c9f9
2024-05-21
Published